Find notable cyber news and cases, enriched with sources, timelines, and signals.

LiteLLM gateways default admin key exposure security flaw

Vulnerability
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

LiteLLM gateways that still accept the default sk-1234 admin key expose administrator access paths, allowing access to stored provider API keys and, in tests, cloud IAM credentials. Wiz Research found the issue on 294 of 3,074 internet-facing instances it scanned in February. The default credential turns an exposed gateway into a high-value secrets store risk. Operators can reduce exposure by replacing the key with a long random value.

Related Happenings

AWS access keys publicly exposed and still valid

Data Leak
H score33 First: 21.08.2026 18:55 Last: 21.08.2026 18:55 Sources 1

About this happening: More than 9,300 AWS access keys exposed in public sources between August 2022 and August 2026 remained active and valid, creating a live risk of cloud account takeover...

Daxin and Stupig active on a Taiwan manufacturing host in 2026

Malware Activity
H score27 First: 16.07.2026 14:17 Last: 16.07.2026 14:17 Sources 1

About this happening: The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...

TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools

Malware Activity
H score36 First: 30.06.2026 18:34 Last: 30.06.2026 18:34 Sources 1

About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...

Trivy environment credentials leak

Data Leak
H score37 First: 21.03.2026 19:30 Last: 21.03.2026 19:30 Sources 1

About this happening: The Trivy environment credentials leak exposed stolen authentication secrets and helped enable a later compromise, raising the risk of follow-on abuse. The credentials came fr...

Bitwarden adds passkey login for Windows 11 sign-in

Security Tool/Service
H score11 First: 05.03.2026 00:34 Last: 05.03.2026 00:34 Sources 1

About this happening: Bitwarden added passkey login for Windows 11, expanding passwordless sign-in and reducing phishing exposure for users who store credentials in the vault.

Timeline

  1. 10.09.2026 10:12 2 articles · 3h ago

    LiteLLM gateways default admin key exposure security flaw

    Initial Disclosure

    In February, Wiz Research found that a substantial share of internet-facing LiteLLM gateways still accepted the default sk-1234 admin key. That left exposed deployments with administrator access to stored secrets and, in tests, cloud credentials.

    Show sources